What a Certificate Authority Does

A certificate authority (CA) is an organization that confirms a website is actually run by the person or company claiming to run it. When you visit a website with "https://" in the address bar, a CA has vouched that the site's owner is legitimate — not an imposter trying to steal your password or payment information.

Think of it like a notary public for the internet. Just as a notary checks your ID before stamping a document, a CA checks that the person requesting a security certificate actually owns the domain name they claim to own. If the check passes, the CA issues a digital certificate that your browser reads and trusts.

Without certificate authorities, your browser would have no way to know whether a website claiming to be your bank is actually your bank or a fake site designed to look identical. The CA's job is to do that verification work so you don't have to.

Key Takeaways

  • A certificate authority verifies that a website owner is who they claim to be before issuing a security certificate.
  • Your browser trusts certain CAs by default, and checks their signature on a website's certificate every time you visit.
  • If a CA issues a certificate to someone who doesn't own a domain, or if a certificate is stolen, your browser may show a warning or block the site.
  • Major CAs include DigiCert, Sectigo, and GlobalSign, but you typically never interact with them directly — your browser does the verification automatically.

How Your Browser Checks a Certificate Authority's Work

When you type a web address into your browser, it downloads the website's security certificate before showing you any content. That certificate contains the CA's digital signature — proof that the CA checked the website owner's identity and approved the certificate.

Your browser has a built-in list of CAs it trusts. It checks whether the signature on the certificate matches one of those trusted CAs. If it does, your browser assumes the website is legitimate and loads the page. If the signature doesn't match, or if the certificate has expired, your browser shows a warning: "This connection is not secure" or "Your connection is not private."

This happens in seconds, without you doing anything. You only notice it when something goes wrong — when a certificate is missing, fake, or out of date.

What Certificate Authorities Actually Verify

A CA doesn't verify that a website is safe or that the company running it is trustworthy. It only verifies that the person requesting the certificate actually owns or controls the domain name. The verification method depends on the type of certificate.

For a basic certificate, the CA might send an email to an address listed in the domain's registration records and ask the owner to click a link. For higher-security certificates used by banks and payment processors, the CA may require documents like a business license, articles of incorporation, or a phone call to a listed business number. The CA checks these documents against public records to confirm the owner is real.

A CA cannot tell you whether a website's content is accurate, whether the company is financially stable, or whether it will deliver what it promises. It only confirms that the domain owner is who they say they are.

Why Your Browser Trusts Certain Certificate Authorities

Your browser comes with a pre-installed list of CAs it considers trustworthy. This list includes organizations like DigiCert, Sectigo, GlobalSign, and Let's Encrypt. These CAs have been vetted by browser makers and operating systems to follow strict rules about how they verify identities and issue certificates.

If a CA issues a certificate to someone who doesn't own a domain, or if it fails to properly verify an owner's identity, browser makers can remove it from the trusted list. This has happened in the past — for example, when a CA issued a certificate for Google's domain to someone who didn't work for Google, the CA lost trust and had to rebuild its reputation.

You can view your browser's trusted CAs in its settings, though most people never need to. The browser handles the verification automatically.

What Happens When a Certificate Authority Makes a Mistake

If a CA issues a certificate to the wrong person — someone who doesn't own the domain — that person can create a fake website that looks identical to the real one. Your browser will show the green lock icon and say the connection is secure, because the certificate is valid. The only way to know you're on a fake site is to look carefully at the web address or notice that something doesn't work the way it normally does.

This is rare, but it has happened. In 2011, a CA issued a certificate for google.com to someone who didn't work for Google. The certificate was caught and revoked, but it showed how much damage a single mistake could cause.

To reduce this risk, CAs now use certificate transparency logs — public records of every certificate they issue. Browser makers and security researchers monitor these logs to spot certificates issued to the wrong owner. If they find one, they can revoke it quickly, and your browser will show a warning if you try to visit the fake site.

Free Certificates and Paid Certificates

Some CAs issue certificates for free, while others charge. Let's Encrypt, a nonprofit CA, issues free certificates to anyone who can prove they own a domain. Paid CAs like DigiCert and Sectigo charge because they offer higher levels of verification or additional features like insurance against fraud.

A free certificate and a paid certificate both do the same basic job: they prove the website owner controls the domain. The difference is in how thoroughly the CA verifies the owner's identity and what happens if something goes wrong. A paid certificate from a reputable CA might include insurance that covers losses if the certificate is misused, while a free certificate does not.

For most websites, a free certificate is sufficient. For sites that handle sensitive information — like banks, payment processors, or healthcare providers — a paid certificate with higher verification is more common, though not required by law.

What Certificate Authorities Cannot Do

A CA cannot protect you from phishing emails that link to fake websites. Even if a fake site has a valid certificate, it's still a fake site — the CA only verified that the certificate owner controls the domain, not that the domain is the real one you intended to visit.

A CA also cannot protect you from malware, viruses, or scams. A legitimate business can get a valid certificate and then use its website to sell counterfeit goods or run a scam. The green lock icon means the connection is encrypted and the domain owner is verified, not that the business is honest.

Certificate authorities are one layer of security. They prevent impersonation of legitimate domains, but they don't prevent fraud or malicious behavior by the legitimate domain owner.

Frequently Asked Questions

What does the green lock icon mean?

The green lock means your browser verified the website's certificate with a trusted certificate authority, and your connection to the site is encrypted. It does not mean the website is safe, trustworthy, or run by an honest business — only that the domain owner is verified and the connection is secure.

Can I see which certificate authority issued a website's certificate?

Yes. In most browsers, click the lock icon next to the web address, then click "Certificate" or "Connection is secure." You'll see the certificate details, including the CA's name. You can also right-click the page, select "Inspect," go to the Security tab, and view the certificate chain.

What should I do if my browser shows a certificate warning?

A certificate warning usually means the certificate is expired, the domain doesn't match the certificate, or the certificate wasn't issued by a trusted CA. Do not enter passwords or payment information on a site showing this warning. If it's a site you normally trust, contact the website owner to report the problem.

Do I need to buy a certificate for my website?

No. Let's Encrypt issues free certificates to anyone who owns a domain. Most web hosting providers can set up a free certificate for you automatically. Paid certificates are optional and useful mainly if you want higher verification levels or fraud insurance.

Can a certificate authority see my passwords or data?

No. The CA only verifies the domain owner's identity and issues a certificate. It does not have access to your data, passwords, or anything you send to the website. The certificate encrypts your connection, but the encryption key is between you and the website, not involving the CA.